[MLUG] Practical Attack on the MIFARE Classic.

Andy Pintar andy at hapoteh.net
Tue Dec 2 15:53:38 EST 2008


Hi;
Just wondering what the status is of the MIFARE/Opus attack.  After 
reading the paper it seemed clear to me that this 'practical attack' isn't 
all that practical and isn't really an attack.  Worst case scenario (the 
way I understood it) is read-only access to some potentially personal 
data.  If the recommendations at the end were followed at all then it 
seems that the card is still quite secure.

Although I'm not an expert in this field, I found this paper was (in my 
opinion) poorly written and unclear.  So, I may have missed a point or two 
with regards to reading or writing.  Any updates on whether the CBC was 
able to walk through the turnstiles?  I'm guessing that this wouldn't be 
possible using only the information provided in this paper.

-Andy.


More information about the mlug mailing list